Cybersecurity Engineer – Splunk SIEM

Hybrid in Richmond, VA, US • Posted 6 hours ago • Updated 6 hours ago
Full Time
No Travel Required
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • Cyber Security
  • SIEM
  • Security Engineering
  • Splunk
  • Network Security
  • SPL
  • Linux
  • Google Cloud Platform

Summary

Cybersecurity Engineer – Splunk SIEM

Location: Richmond, VA Metro Area
Work Arrangement: Hybrid
Employment Type: Contract
Client: Virginia Government Agency

Job Overview

We are seeking an experienced Cybersecurity Engineer with strong expertise in Splunk SIEM and Splunk Enterprise Security (ES) to support advanced cyber defense initiatives.

The Cybersecurity Engineer will be responsible for monitoring, detecting, analyzing, and responding to security threats across enterprise environments. The ideal candidate will have hands-on experience with Splunk queries, log analysis, threat hunting, correlation searches, dashboards, incident response, and security use-case development.

The engineer will work closely with cybersecurity, infrastructure, network, cloud, and IT teams to strengthen security monitoring and improve threat detection capabilities.

Key Responsibilities

  • Monitor network, endpoint, server, application, and cloud security logs for suspicious and anomalous activity.

  • Use Splunk Enterprise Security to identify, investigate, and respond to potential security incidents.

  • Develop, maintain, and tune Splunk correlation searches, alerts, dashboards, and reports.

  • Write and optimize SPL (Search Processing Language) queries for security monitoring and threat detection.

  • Perform proactive threat hunting across enterprise security data.

  • Investigate security alerts and incidents using log analysis and forensic evidence.

  • Collaborate with infrastructure, networking, cloud, and application teams to contain and remediate security threats.

  • Develop and enhance security detection use cases based on emerging threats and organizational requirements.

  • Map detection capabilities to frameworks such as MITRE ATT&CK.

  • Develop and maintain incident response procedures, detection logic, and security playbooks.

  • Onboard new security and infrastructure data sources into Splunk.

  • Configure and troubleshoot log ingestion, parsing, field extraction, and normalization.

  • Monitor data quality and ensure logs are properly indexed and searchable.

  • Tune security detections to reduce false positives and improve detection accuracy.

  • Support security investigations involving endpoints, servers, networks, applications, and cloud environments.

  • Assist with security audits, compliance activities, and evidence collection.

  • Generate SIEM reports and documentation aligned with organizational security policies and standards.

  • Stay current with emerging cyber threats, vulnerabilities, attack techniques, and security technologies.

Required Skills & Experience

  • 5+ years of experience in Cybersecurity, Security Engineering, SIEM, or Security Operations.

  • Strong hands-on experience with Splunk Enterprise Security (ES).

  • Strong knowledge of Splunk SPL/Search Processing Language.

  • Experience developing and tuning correlation searches and security alerts.

  • Experience creating Splunk dashboards, reports, and security monitoring use cases.

  • Strong understanding of SIEM concepts and security event monitoring.

  • Hands-on experience with log analysis and threat hunting.

  • Experience investigating and responding to security incidents.

  • Knowledge of MITRE ATT&CK framework and security detection techniques.

  • Experience onboarding and integrating security data sources into Splunk.

  • Understanding of log parsing, normalization, field extraction, and data ingestion.

  • Knowledge of network security, endpoint security, authentication, and cloud security logs.

  • Strong analytical and troubleshooting skills.

  • Excellent written and verbal communication skills.

Preferred Qualifications

  • Splunk certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk Enterprise Security Certified Admin.

  • Experience with SOAR platforms and security automation.

  • Experience with EDR/XDR technologies.

  • Knowledge of Microsoft Sentinel, QRadar, or other SIEM platforms.

  • Experience with cloud security monitoring across Azure, AWS, or Google Cloud Platform.

  • Knowledge of incident response and digital forensics.

  • Familiarity with security frameworks including NIST, CIS, and MITRE ATT&CK.

  • Relevant cybersecurity certifications such as CISSP, Security+, CySA+, GCIH, IA.

Technical Skills

SIEM: Splunk, Splunk Enterprise Security
Query Language: SPL
Security: Threat Detection, Threat Hunting, Incident Response, Security Monitoring
Frameworks: MITRE ATT&CK, NIST, CIS
Logging: Windows, Linux, Network, Firewall, Endpoint, Cloud, Application Logs
Cloud: Azure, AWS, Google Cloud Platform
Security Tools: EDR, XDR, SOAR, IDS/IPS, Firewalls
Automation: Security Playbooks, Alert Automation, SOAR
Compliance: Security Audits, SIEM Evidence, Compliance Reporting

Ideal Candidate

The ideal candidate is a hands-on Splunk Cybersecurity Engineer who can independently:

  • Write complex SPL queries

  • Build and tune Splunk correlation searches

  • Develop security dashboards and alerts

  • Perform threat hunting

  • Investigate security incidents

  • Onboard and troubleshoot log sources

  • Develop detection use cases mapped to MITRE ATT&CK

  • Reduce false positives

  • Work with infrastructure and network teams during incident response

Strong Splunk SIEM + SPL + Threat Hunting + Incident Response experience is highly preferred.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91052859
  • Position Id: 9056382
  • Posted 6 hours ago
Contact the job poster
Bheeshma Maha

Bheeshma Maha

Recruiter @ Data Capital Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Richmond, Virginia

14d ago

Easy Apply

Contract

65 - 70

Richmond, Virginia

Today

Full-time

USD 62.00 - 82.00 per hour

Richmond, Virginia

Today

Easy Apply

Full-time

$100,000 - $115,000

Richmond, Virginia

11d ago

Easy Apply

Third Party, Contract

Depends on Experience

Search all similar jobs